Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 28, 2026 · 7 min read

CPJ: Ad Tech Location Data Puts Journalists at Risk

A joint report from the Committee to Protect Journalists and Harvard Kennedy School’s Carr-Ryan Center, published August 27, 2026, shows the ad auction funding the open web also puts reporters’ movements up for sale.

A Belgian reporter asked a United States data broker for a sample of its location inventory. It arrived free of charge: roughly one million devices and about 100 million location points, harvested from a two week window in 2025. Nicolas Baudoux and his colleagues at L’Echo opened the file and began picking out individuals by name.

That sample is the sharp end of a larger finding. CPJ’s report, by deputy director of research and analysis Jonathan Rozen, argues that the machinery built to sell banner ads is now the cheapest surveillance system ever assembled.

Key Takeaways

  • The Committee to Protect Journalists and Harvard Kennedy School’s Carr-Ryan Center for Human Rights published a joint special report on August 27, 2026 on advertising surveillance and the press.
  • L’Echo reporter Nicolas Baudoux obtained a free data broker sample covering roughly one million devices and about 100 million location points from two weeks of 2025.
  • Basma Mostafa, an Egyptian journalist living in exile in Berlin, appeared in a commercially available dataset that revealed her home and her pattern of life.
  • The Irish Council for Civil Liberties estimates real time bidding broadcasts what people view and where they are 178 trillion times a year across the United States and Europe.
  • The US Federal Trade Commission stated in July 2024 that hashed and pseudonymous identifiers, advertising IDs included, remain identifiable data.

What Did CPJ Actually Find?

CPJ found that data from ordinary phone apps is resold in bulk, cheaply enough that a newsroom can obtain a usable sample for nothing, and precisely enough to show where a specific journalist sleeps, works, and meets people. The full report traces three cases.

Run the arithmetic on Baudoux’s file. One hundred million points across one million devices over 14 days is roughly 100 pings per phone, one location fix every three and a half hours. Nobody in it agreed to be followed at that cadence. They agreed to a cookie banner.

The second case is Ingo Dachwitz of netzpolitik.org, who found his own movements in a free database sample after granting location access to exactly one app: a weather app. He called it “very spooky.” The third is Basma Mostafa, an Egyptian journalist in exile in Berlin. German reporters found her in a commercial dataset that laid out her home and the places she visited. Egyptian authorities can buy the same file.

How Does Real Time Bidding Leak Your Location?

Real time bidding leaks location because every ad slot you load broadcasts your device data to hundreds of potential bidders, and receiving that broadcast costs nothing. The exchange assembles a bid request holding an advertising ID, an IP address, coordinates, device model, and the app you are in, then sends it to every accredited bidder at once. The auction closes in under 100 milliseconds. One company wins and shows an ad. Everyone else keeps a copy.

That asymmetry is the whole vulnerability. A firm that registers as a bidder, bids on nothing, and simply logs what arrives has built a global tracking network without buying one impression. The Irish Council for Civil Liberties puts those broadcasts at 178 trillion a year across the US and Europe, exposing the average European 376 times a day and the average American 747.

The pipeline does not stop at the exchange. SDKs bundled into free apps collect coordinates directly and sell them onward. Three weeks before CPJ published, the Electronic Frontier Foundation reported that InMobi and three other Android ad SDKs collect location by default, without the developer asking. Dachwitz’s weather app is that finding with a name attached.

A journalist’s notebook, phone and coffee on a darkened newsroom desk seen through a window with faint city lights and a blurred map reflection on the glass

Why an Advertising ID Is Not Anonymous

An advertising ID is not anonymous because location history identifies you without your name. The regulator has said so plainly: in a July 2024 post titled No, hashing still doesn’t make your data anonymous, the FTC held that hashed emails, device identifiers, and advertising identifiers are identifiable data.

The unmasking method is dull and reliable: the coordinates where a device rests every night plus the ones where it sits on weekday afternoons narrow almost any adult to one person, and property records finish the job.

Brokers then stitch that identifier to an email address, a phone number, and a postal address, and license the joined record to whoever pays. Gblock covered the pattern when ICE spent $6.7 million on LexisNexis records piped into Palantir. The buyer changes. The inventory does not.

Why Is This a Press Freedom Problem?

Because a location trail is a source list. A reporter’s device does not need to record a conversation to burn the person who had it. Two devices resting in the same café for 40 minutes, twice, three weeks apart, is enough for anyone holding both trails to infer a relationship. Confidential sourcing survives on the assumption that nobody can retroactively enumerate every place a journalist stood. The same assumption underwrites reading trails, which is why X shutting down Nitter matters to the same reporters: monitoring an account now requires an account, and an account is an identity.

Exiled reporters carry the sharpest version. Mostafa left Egypt; her phone did not stop broadcasting. A government that cannot compel a German telecom can still buy a commercial dataset through an intermediary and search it, with no warrant, no spyware licence, and no cooperation from any platform. It is also far cheaper than Pegasus. Surveillance systems get repurposed by whoever holds the console, as when a police officer ran his girlfriend’s licence plate 124 times through Flock’s camera network. Ad tech has no console and no audit log at all.

Why Hasn’t GDPR Stopped This?

GDPR has not stopped RTB because enforcement landed on the consent pop up rather than the auction behind it. The Belgian Data Protection Authority fined IAB Europe €250,000 in 2022 over the Transparency and Consent Framework, the standard nearly every European exchange uses.

The Court of Justice of the European Union confirmed in Case C-604/22 in March 2024 that the TC String encoding your choices is personal data. On 15 May 2025 the Brussels Market Court upheld the fine, then narrowed it: IAB Europe is a joint controller for the consent string, not for what bidders do downstream.

Most coverage read that as a partial industry win. The more uncomfortable reading: seven years of complaints produced a quarter million euro penalty against the layer that records your answer, while the layer broadcasting your coordinates 376 times a day has never been fined. The pop up got regulated. The auction did not.

The Inbox Branch of the Same Pipeline

Email tracking is the same industry pointed at a different surface. A tracking pixel is a one by one image on a marketing server, and loading it hands over your IP address, approximate city, device, mail client, and the second you opened the message. Those are the identifiers RTB trades in, resolved against something better than an advertising ID: a verified email address, the primary join key brokers use to merge datasets.

For a reporter the exposure is timing and travel rather than a street address. A press release opened at 02:14 from an IP in another country tells the sender you have moved. To see which trackers already follow you, DecryptAds maps the companies watching a given site, and the overlap with the exchanges CPJ names is not a coincidence.

Be precise about what this fixes. Blocking email beacons and rewritten tracking links removes one input to the identifier graph. It does nothing about an SDK inside a weather app, and no extension can pull your device out of a broker’s existing location file. Blocking spy pixels in Gmail closes one door in a building with many.

What Can Journalists Do Right Now?

Start with the identifier that ties the file together, then cut the apps feeding it. CPJ published a companion guide, Protecting against advertising technology, alongside the report. The same identifier problem runs through the doxxing playbook: EFF's doxxing guide leaves out the one address that stitches the file together, and it is the email you have reused since 2011.

  • Delete your advertising ID. On Android: Settings, Privacy, Ads, Delete advertising ID. On iOS, switch off Allow Apps to Request to Track, per Apple’s App Tracking Transparency guidance.
  • Audit location permissions app by app. Anything that is not a map should be Never or While Using. Weather, flashlight, and free game apps are the classic SDK carriers.
  • Turn off precise location where an app needs only rough geography. Coarse coordinates still power a forecast and break pattern of life analysis.
  • Run tracker blocking at the DNS or browser layer so exchanges never see the request.
  • Carry a separate, minimal device for source meetings, with no ad supported apps and location switched off.
  • Block remote images and email pixels on the account you use for professional correspondence.

CPJ is blunt that these are mitigations, not a fix. The report also puts an awkward question to newsrooms: most news sites monetise through the same RTB pipeline, and can expose their own reporters and readers while writing about surveillance.

What to Watch Next

Watch whether any regulator goes after bid requests directly rather than consent strings. Until one does, the asymmetry stands: buying a journalist’s movements takes a corporate email address and a request form, while undoing that exposure takes a device rebuild. Gblock has covered the downstream end of this market before, including Proton’s discovery of 116,000 journalist records on dark web forums.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.